Known vulnerabilities in Enterprise SONiC - page 2

Vendor: Dell
Software CPE: cpe:2.3:a:dell:enterprise_sonic:*:*:*:*:*:*:*:*
Total vulnerabilities: 105
Public exploits: 10
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Enterprise SONiC Enterprise SONiC is affected by 105 known vulnerabilities: 16 high, 52 medium, 37 low Critical High Medium Low

Vulnerabilities (105)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU95339 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-6345
CWE-94 High
No
No
4.4.1 05.08.2024 SB2024080590
SB2024080593
SB2024080594
and 160 more
#VU93519 - Out-of-bounds read
CVE-2024-37371
CWE-125 Medium
No
No
4.4.1 01.07.2024 SB2024070148
SB2024070491
SB2024070496
and 114 more
#VU93518 - Improper input validation
CVE-2024-37370
CWE-20 Medium
No
No
4.4.1 01.07.2024 SB2024070148
SB2024070491
SB2024070496
and 96 more
#VU87672 - Improper input validation
CVE-2024-28835
CWE-20 Medium
No
No
4.4.1 20.03.2024 SB2024032057
SB2024032058
SB2024032059
and 71 more
#VU87671 - Cryptographic Issues
CVE-2024-28834
CWE-310 Medium
No
No
4.4.1 20.03.2024 SB2024032057
SB2024032058
SB2024032059
and 111 more
#VU84789 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-51385
CWE-78 Medium
Available
No
4.2.1 26.12.2023 SB2023121905
SB2023122710
SB2023122801
and 65 more
#VU81436 - Out-of-bounds read
CVE-2023-43789
CWE-125 Low
No
No
4.2.1 03.10.2023 SB2023100342
SB2023100346
SB2023100424
and 36 more
#VU81435 - Out-of-bounds read
CVE-2023-43788
CWE-125 Low
No
No
4.2.1 03.10.2023 SB2023100342
SB2023100346
SB2023100424
and 37 more
#VU75141 - Memory corruption
CVE-2023-29491
CWE-119 Low
No
No
4.2.1 14.04.2023 SB2023041454
SB2023052328
SB2023052346
and 132 more
#VU70879 - NULL Pointer Dereference
CVE-2022-44793
CWE-476 Medium
Available
No
4.1.4 10.01.2023 SB2023011024
SB2023011029
SB2023011140
and 18 more
#VU70878 - NULL Pointer Dereference
CVE-2022-44792
CWE-476 Medium
Available
No
4.1.4 10.01.2023 SB2023011024
SB2023011029
SB2023011140
and 17 more
#VU65676 - NULL Pointer Dereference
CVE-2022-24810
CWE-476 Low
No
No
4.1.4 21.07.2022 SB2022072138
SB2022072139
SB2022080133
and 16 more
#VU65675 - NULL Pointer Dereference
CVE-2022-24808
CWE-476 Low
No
No
4.1.4 21.07.2022 SB2022072138
SB2022072139
SB2022080133
and 17 more
#VU65674 - Out-of-bounds write
CVE-2022-24807
CWE-787 Medium
No
No
4.1.4 21.07.2022 SB2022072138
SB2022072139
SB2022080133
and 16 more
#VU65673 - Improper input validation
CVE-2022-24806
CWE-20 Low
No
No
4.1.4 21.07.2022 SB2022072138
SB2022072139
SB2022080133
and 16 more
#VU65672 - NULL Pointer Dereference
CVE-2022-24809
CWE-476 Low
No
No
4.1.4 21.07.2022 SB2022072138
SB2022072139
SB2022080133
and 17 more
#VU65671 - Out-of-bounds write
CVE-2022-24805
CWE-787 Medium
No
No
4.1.4 21.07.2022 SB2022072138
SB2022072139
SB2022080133
and 19 more
#VU57577 - Out-of-bounds write
CVE-2021-39537
CWE-787 High
No
No
4.2.1 21.10.2021 SB2021102119
SB2022061419
SB2021102025
and 18 more
#VU45745 - Incorrect Permission Assignment for Critical Resource
CVE-2020-15862
CWE-732 Medium
No
No
4.1.4 17.08.2020 SB2020081707
SB2020082704
SB2020111826
and 22 more
#VU45744 - UNIX Symbolic Link (Symlink) Following
CVE-2020-15861
CWE-61 Low
No
No
4.1.4 17.08.2020 SB2020081705
SB2020081706
SB2020082704
and 3 more


Showing elements 21 - 40 out of 105